This repository contains my hands-on penetration testing practice labs based on real-world attack methodology and the Cyber Kill Chain model.
To simulate real-world attacks in a controlled lab environment and document reconnaissance, exploitation, and defense techniques.
- Information Gathering
- Nmap Scanning
- Whois Lookup
- DNS Enumeration
Tools Used:
- Nmap
- Whois
- theHarvester
Screenshots: (Insert images here)
- Port scanning
- Service version detection
- SMB enumeration
- Directory brute forcing
Tools Used:
- Nmap
- enum4linux
- Gobuster
- Vulnerability identification
- Metasploit exploitation
- Web app attacks (SQLi / XSS)
Tools Used:
- Metasploit
- Burp Suite
- Privilege escalation
- Persistence
- Data extraction
Tools Used:
- Linux commands
- Meterpreter
- Kali Linux (Attacker)
- Metasploitable 2 (Target)
- VirtualBox
- Understanding attack flow
- Identifying weak services
- Practical exploitation workflow
- Defensive thinking from attacker perspective